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HIDING OF ENCRYPTED DATA 

Field of the Invention 

The present invention relates to methods and apparatus for hiding data 
5 within a digital signal, and particularly for concealing information within multimedia 
signals such as digital image, audio, or video signals. More particularly, the present 
invention relates to methods and apparatus for embedding and retrieving information into 
and out of a digital signal used in multimedia applications while minimizing the effect on 
the multimedia application of the digital signal. 

10 

Rar.lf pronnd and Summary of the Invention 

The art of concealing information has existed for millennia and is one to 
which computers have been readily adapted. It is known, for example, to use computers 
for encrypting data using various symmetric and asymmetric cryptographic schemes such 

1 5 as the Data Encryption Standard (DES) and RS A encryption, and cryptographic software 
packages such as PGP (Pretty Good Privacy). Another technique for concealing 
information for which computers are used is data hiding or steganography, in which the 
existence of certain information is concealed within a carrier communication. In contrast 
to cryptography, where it is a goal to make a message undecipherable regardless of its 

20 detection, with steganography it is a goal to hide the very existence of the hidden 

message. An example of a known steganography technique using computers is to embed 
a digital watermark into a digital image. 

According to the present invention, a method of hiding data is provided. 
A message to be hidden and an encrypting sequence are provided along with a carrier 

25 signal that conveys information (unrelated to the message). An encrypted message is 

generated based on the message and the encrypting sequence. The encrypted message is 
embedded into the carrier signal by performing an exclusive-OR of the encrypted message 
with a first portion of the carrier signal. 

In preferred embodiments, the carrier signal is a digital image, and the first 

30 portion of the carrier signal is an LSB plane of the digital image. The digital image has a 
plurality of color planes, the first portion of the carrier signal is an LSB plane of a first 
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color plane, and the second portion of the carrier signal is an LSB plane of a second color 
plane. 

According to another aspect of the invention, the carrier signal is 
transmitted to a receiving location. The encrypted message is extracted and from the 
5 carrier signal and deciphered at the receiving location. In preferred embodiments, the 
encrypted sequence is generated based on an encrypting key. The encrypted message is 
generated by performing an exclusive-OR of the message with the encrypting sequence. 

According to yet another aspect of the invention, a method of data hiding 
is provided in which an encryption key and a carrier signal that conveys information 
10 unrelated to the encryption key are supplied. An encryption sequence based on the 

encryption key is generated. The encryption sequence is embedded into the carrier signal. 

In preferred embodiments, the encryption key is a public key for an 
asymmetric encryption algorithm. The carrier signal can be a signal such as a digital 
image, digital audio, or digital video. The encryption sequence is substantially random, 
15 and can be generated based on a linear feedback shift register. The encryption sequence is 
embedded into the carrier signal by performing an exclusive-OR of the encryption 
sequence with a portion of the carrier signal. 

According to other aspects of the invention, the carrier signal including the 
embedded encryption sequence is transmitted to a receiving location. The encryption 
20 sequence is extracted from the composite signal at the receiving location. The encryption 
sequence is decrypted to obtain the encryption key. The encryption key is used to 
generate an encrypted message at the receiving location, and the encrypted message is 
transmitted from the receiving location. 

According to yet another aspect of the invention, a method of data hiding 
25 is provided. An encrypted message is embedded into a first portion of a carrier signal and 
message extraction information is embedded into a second portion of the carrier signal for 
extracting the encrypted message from the first portion of the carrier signal. 

In preferred embodiments, the encrypted message is embedded by 
performing an exclusive-OR of the encrypted message with the first portion of the carrier 
30 signal. The message extraction information is embedded by performing an exclusive-OR 
of the first portion of the carrier signal with the second portion of the carrier signal. The 
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first and second portions of the carrier signal can be first and second bit-planes of a digital 
image. 

According to still another aspect of the invention, a method of exchanging 
data hidden in a carrier signal is provided. A signal including hidden data is generated by 

5 transforming a carrier signal from a first domain into a second domain. A message is 
embedded into the carrier signal in the second domain. The carrier signal is transformed 
back from the second domain to the first domain. The signal including hidden data is sent 
to a receiving location. The message is obtained from the signal including hidden data at 
the receiving location by transforming the signal including hidden data into the second 

1 0 domain and extracting the message. 

In preferred embodiments, the message is encrypted prior to generating the 
signal including hidden data. The message is decrypted after obtaining the message from 
the signal including hidden data. 

According to still yet another aspect of the invention, a data hiding 

15 apparatus is provided. An encryption sequence generator generates an encryption 

sequence based on an encrypting key. An encrypted message generator generates an 
encrypted message based on the encryption sequence and an input message. An 
encrypted message embedder embeds the encrypted message into a carrier signal. 

In preferred embodiments, the encryption sequence generator generates a 

20 substantially random encryption sequence. The encrypted message embedder performs an 
exclusive-OR of the encrypted message with a portion of the carrier signal. The 
encrypted message embedder replaces a first LSB plane of a digital image with 
information based on a second LSB plane of the digital image and performs an exclusive- 
OR of the encrypted message with the second LSB plane of the digital image: The 

25 encrypted message generator performs an exclusive-OR of the input message with the 
encrypting sequence to generate the encrypted message. 

Additional features of the invention will become apparent to those skilled 
in the art upon consideration of the following detailed description of the preferred 
embodiments exemplifying the best mode of carrying out the invention as presently 

30 perceived. 
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Brief Description of the Drawings 

Fig. 1 is a block diagram of two computer systems connected over a 
network, each computer system configured with a processor and memory for 
implementing embodiments of the present invention; 
5 Fig. 2 is a flow chart showing a method according to the present invention 

for hiding data within an image for transmission over a network; 

Fig. 3 is a high level block diagram showing a technique for embedding 
encrypted information into a carrier signal; 

Fig. 4 is a more detailed block diagram similar to Fig. 3 showing a similar, 
10 more specific technique for embedding encrypted information into a carrier signal; 

Fig. 5 is a stylized representation of a message format containing 
embedded, hidden information; 

Fig. 6 is a stylized representation similar to Fig. 5 of an alternative message 

format; and 

15 Fig. 7 is a flow chart showing an alternative method according to the 

present invention for hiding data within an image for transmission over a network. 

Detailed Description of the Illustrative Embodiments 

The present invention lends itself to implementation in a conventional 
20 computer network 10 as shown in Fig. 1. Computer network 10 illustratively includes 

computer systems 12, 18 connected through a series of network communication devices 

14, 16, 20 (e.g., modems, transceivers, etc.) for communication over a network 22 such 

as the standard telephone lines, or the Internet or World Wide Web. Computer systems 

12, 18 are illustratively personal computers and each includes basic elements such as a 
25 processor 26, 32, memory 28, 34, storage device 30, 36, and display 31, 38. Computer 

systems 12, 18 can also include optional peripheral devices such as removable storage 

device 40 (e.g., a CD-ROM or 3 ! /2 inch disk drive). 

An exemplary method of data hiding according to the present invention 

that is suitable for carrying out on computer network 10 is shown in Fig. 2. Although the 
30 present invention is disclosed in the context of certain embodiments discussing digital 

images, other digital signals, such as digital audio or video signals, are also within the 

scope of the invention. 



WO 99/11020 



PCT/US98/17321 



-5- 

According to the method of Fig. 2, an image is used to transport and 
exchange data that is embedded in the image itself and that cannot be perceived by the 
human eye. An appropriate analogy is that the image acts as an envelope, with the 
embedded data transmitted with the image being equivalent to a letter contained within 
5 the envelope. Conventional encryption such as PGP or RSA is used to enhance security 
of the embedded data. The security is improved because the encrypted data is hidden 
within the image and therefore cannot be recognized as such. This allows for secure data 
communication and exchange over an insecure transmission channel. 

In step 50 an original digital image is obtained. A secret message that is 
10 desired to be embedded into the image is generated in step 52. A message encrypting key 
is used in step 54 to generate an encryption sequence. The message encrypting key can 
be a seed value for use in generating an m-sequence from a linear feedback shift register 
as discussed in more detail below, although it is understood that any suitable message 
encrypting algorithm can be used. As also discussed below, the message encrypting key 
15 will ultimately be used by the recipient of the image embedded with the secret message. 

In step 56 the secret message from step 52 is encrypted with the 
encryption sequence from step 54 to create an encrypted message. The encrypted 
message is then embedded into the image in step 58. There are many methods to embed 
the encrypted message into the image such as the method discussed below, but, again, it is 
20 understood that other suitable methods can be used. 

The image with the embedded message is then made available such as on a 
public network as shown in step 60. Finally, if the secret message from step 52 is actually 
information that is not desired to be kept secret, such as a public key for an asymmetric 
encryption algorithm, then the encryption key from step 54 is also made available on the 
25 public network as shown in steps 62, 64. This allows for third parties to extract the 

message from the image. Thus, for example, the message can be a public encryption key 
that is hidden within the image but that is readily available to a party that has knowledge 
of the fact that the hidden message exists. This provides a convenient way of exchanging 
information, such as allowing an individual to make a public encryption key available over 
30 the World Wide Web by posting it within an image on a Web site, while still concealing 
the information from the casual observer. 
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It is useful at this point to provide some preliminary definitions before 
discussing a specific implementation of the method of Fig. 2. The symbol © denotes a bit 
excIusive-OR function (equivalent ly, modulo-2 addition). Table 1 illustrates the 
exclusive-OR function: 
5 Table 1 

Jl. b_ a <?p 

0 0 0 

0 1 1 

1 0 1 

10 110 

A digital image is typically represented with a two dimensional array of 
pixel values. If A is the array of pixel values, then A(x,y) denotes the pixel value in the 
x-th column of the y-th row of the array. Each index x,y begins at zero, and by 
15 convention the origin is at the upper-left corner with positive coordinates going 
rightwards and downwards, although this convention is somewhat arbitrary. 

For labeling purposes, it will be assumed that the digital image is a 24-bit 
RGB image with pixel values ordered as shown in Table 2: xx 

Table2 

20 MSB LSB 

E£d Green Blue 

23 22 21 20 19 18 17 16 15 14 13 12 11 10 9 8 7 6 S 4 3 2 1 0 
R7 R6 R5 R4 R3 R2 Rl R0 G7 G6 G5 G4 G3 G2 Gl GO B7 B6 B5 B4 B3 B2 Bl BO 

25 Thus, bits 16-23 refer to the red component, bits 8-15 refer to the green 

component, and bits 0-7 refer to the blue component for any given pixel value. For 
example, Iao( x >y) refers to the least-significant bit of the green component of the (x,y)- 
pixel in the image I. Since bit GO is equivalent to bit 8, Ioo( x >y) * s equivalent to I 8 (x,y). 
As with the array convention, this labeling convention is somewhat arbitrary. 

30 An m-sequence is a pseudo-random sequence of binary digits (bits). 

m-sequences have good statistical properties and can be generated by linear feedback shift 
registers (configured appropriately as is known in the art). Knowing the size (number of 
bits), structure (the feedback configuration), and initial fill (the initial contents of each bit) 
of the shift register allows the reconstruction of the entire m-sequence. The m-sequences 

35 here illustratively are generated by a 96-bit m-sequence generator. If the structure and 
size of the shift register are known (as would be the case with this embodiment), and if a 
consecutive portion of the m-sequence equal to twice the shift register size is also known, 
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the initial fill used to generate the sequence can be determined. In this embodiment the 
initial fill is used as the key that generates the m-sequence. In this way, the key can be 
determined from the sequence itself by techniques known to those skilled in cryptography. 

When embedding a message into a carrier signal, the order in which pixel 
5 operations are performed may be an important consideration. A sequence function z(i) is 
defined to provide a one-to-one mapping from i->(x,y), where i is an ordinal number and 
(x,y) refers to coordinate values in an image. The ordinal i ranges from zero to N-l, 
where N is the total number of pixels in the image. Given a sequence function z(i), one 
can compute z(0), z(l), z(2), etc., to obtain a sequence of pixel coordinates (x^), 
10 (x 2 ,y 2 ), etc. As an example, z(i) « (i mod ImageWidth, \\ I ImageWidthJ) denotes a 
sequence beginning at the origin and proceeding in a row-by-row fashion. 

Given these preliminary definitions, an implementation corresponding to 
the illustrative method of Fig. 2 of embedding a message into an image is shown by the 
block diagram in Fig. 3. Input signals are a source image 66 (obtained in step 50), an 
15 unencrypted message 68 (generated in step 52), and an encrypting key 70 (used in step 

54). Message 68 and encrypting key 70 are processed by an encrypted message generator 
76 to create an encrypted message signal 72. Encrypted message 72 is an input along 
with source image 66 into composite signal generator 78, which creates a composite 
signal 74 containing source image signal 66 embedded with encrypted message 72. 
20 Composite signal generator 78 illustratively embeds encrypted message 72 

into the least-significant bit in the green plane Ioo(x,y) of source image 66 to create a new 
least-significant green bit-plane FooOcy) of composite signal 74. In order subsequently to 
extract encrypted message 72 from composite signal 74 (T) it will be necessary to know 
the original values ofUxj) from source image 66. This can of course easily be 
25 accomplished by making the original, unmodified image signal 66 available. Composite 
signal generator 78, however, eliminates the requirement of using original image signal 66 
by encoding the original Ioo(x,y) into the least-significant red bit-plane I , R0 (x,y) of 
composite signal 74 as discussed below. Thus, in order to extract the embedded 
encrypted message 72, only composite signal 74 and the encrypting key 70 are needed. 
30 In order to use the method of Figs. 2 and 3 both a sender and receiver of 

composite signal 74 will need an m-bit shift register with identical feedback configurations 
and a well-defined ordering function z(i) for any arbitrary image. The following steps 
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20 



describe the generation of ihe composite signal 74 (also referred to as public image F) 
from original signal 66 (also referred to as original image I), unencrypted message 68 
(illustratively a public encryption key, also referred to as K PUB ), and encrypting key 70 
(also referred to as K,). As intimated above, encrypting key 70 (Kj) is the initial fill of the 
m-sequence generator. 

In order to generate F, V is initially set to be an exact copy of I. I* is then 
traversed in order z(i) and the red and green least-significant bit planes are set to: 

I'ro(z(0) = I'go(z(0) © m-seq(2i) 

I'o^zO)) = K PUB (i) © r G0 (z(i)) © m-seq(2i+l) 



where K PUB (i) refers to the I-th bit of K PUB , and m-seq(j) refers to the j-th bit in the m- 
sequence using K, as the initial fill. With these two equations, information on portion 2 of 
15 the image (the green LSB plane) is first placed in portion 1 of the image (the red LSB 
plane). Then, the message is embedded in portion 2. 

To recover K PUB it is only necessary to have the composite signal or public 
image F and the encrypting key K r For each pixel in F and in the order z(i), the first step 
is to extract I G0 *(z(i)) by using the least-significant red bit plane and the m-sequence: 



Igo*(z(0) = I'ro(z(0) ® m-seq(2i) 



Ioo*(z(i)) is identical to Igo( 2 (0) *f there 

are no errors in F. Then the i-th bit of K PUB (i) is 

computed by using I G0 *(z(i)): 

25 

K^O) - FGo(z(i)) © Igo*(zO)) © m-seq(2i+l) 

Thus, given K„ it is possible to reconstruct the same m-sequence used to generate F. 
Thus, if no errors occur K PUB * should be identical to Kp^. Thus, the method of the 
30 invention provides for including within the image both the message that is embedded or 
encrypted in the image as well as the information needed to extract or decrypt the 
message from the image. 
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A more specific method corresponding to an implementation of the 
method of Figs. 2 and 3 is shown Fig. 4. The same input signals are used, that is, source 
image 66 (I), message 68 (here, Q instead of K PUB ), and encrypting key 70 (K,) are used. 
The primary refinement in the method of Fig. 4 as compared with Fig. 3 is an encoding 
5 process to handle varying length messages 68. 

Message 68, which in the example of Fig. 3 was a public encryption key 
for use in an asymmetric cryptography system, can more generally simply be a collection 
of bits intended to be encrypted and is referred to here as Q. The length (i.e., the total 
number of bits) of Q is denoted |Q| . The i-th bit of the message Q is denoted Q(i), where 
10 the bits are numbered from 0 to | Q | - 1 . 

Message 68 (Q) is an input signal to message generator 82 which has as a 
second input the output from a random noise generator 84. Random noise generator 84 
illustratively is also a 96-bit m-sequence generator using an initial fill of a computer 
system time value, although other suitable random signal generators can be used. 
15 Encrypting key 70 (K,) is an input signal (initial fill) to an m-sequence generator 80 that 
illustratively is the same as random noise generator 84, which then generates as an output 
an encrypting sequence 86. 

Unless the message 68 (Q) will always be the same length (in bits) and that 
length is the number of pixels in the source image, it will not be possible to embed Q 
20 directly onto source image 66 (I). It is therefore necessary to encode additional 

information that will enable subsequent extraction of messages Q of varying sizes from 
composite signal 74 (F). Thus, the message 88 to be encoded onto image 66 (I) is 
generated by message generator 82 with special properties and is denoted Q' to show that 
it is derived from Q. 

25 Q' has the following properties. For any given source image I, regardless 

of what message Q is being encoded, the size of a message Q' is the same as the total 
number of pixels in image I (that is, |Q' | = # pixels in I). The bits of message Q' are 
labeled according to standard convention, that is, the first bit (or the left-most bit if Q' is 
viewed as an ordered bit stream from left to right as shown in Fig. 5) is numbered zero. 

30 Thus the bits of Q' are numbered from zero to |Q*|-1. 

The structure of Q' is shown in Fig. 5. All bits except the last sixty-four 
form a date area 92. The last sixty-four bits consist of two thirty-two bit words (StartPos 
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and Length, in that order), which form a Trailer. Data area 92 includes data bits 98 that 
correspond to the message Q itself, and random bits 97, 99 that help hide the location of 
Q (bits 98) within Q\ As part of the encoding process, message generator 82 computes 
the length of message Q and stores its value in the final 32 bits 94 of the Trailer. The 
5 value of the length is not directly encoded and instead a value congruent (actual length 
modulo Data Area size) is placed in the 32-bit word. It is trivial to recover the length 
from this encoded value. 

Starting position 94 describes the location within data area 92 where the 
bits of the message Q reside. Message generator 82 randomly chooses a place 98 to store 

10 Q and populates all other bits of unused portions 97, 99 in data area 92 with random 

noise generated by random noise generator 84. Thus, Q can be anywhere in data area 92. 
Including noise for portions 97, 99 of data area 92 unused by message Q improves 
security of data embedded within I because the noise increases the difficulty of 
recognizing the existence or location of Q within the data area. 

15 The encoding of each bit of message Q* is encoded onto image I on a one- 

bit per one-pixel basis using an exclusive-OR as discussed above for the method of Fig. 3. 
First, the output of m-sequence generator 80 (with K, as a seed value) is used to encrypt 
Q' in encrypter 90. Next, the encrypted Q' is embedded onto the LSB green plane I^. 
Encrypted message Q is subsequently extracted from Q' by locating its starting position 

20 and length from the trailer. The extracted Q is then decoded as discussed above. 

Further implementation steps can be taken to increase security for message 
Q\ Random number generator 84 and m-sequence generator 80 can be different. Even if 
both use 96-bit m-sequence generators, this can be achieved simply by changing the 
feedback coefficients. Moreover, the message length 94 in the trailer can be relocated to 

25 data area 92 as shown in Fig. 6. This relocation will limit the ability of an attacker to take 
advantage of a known size of message Q. 

Another way to provide for security of data hidden within a carrier image 
is shown by the method of Fig. 7. In step 102 the carrier image is transformed from a first 
domain to a second domain. For example, a typical RGB image that is considered to be 

30 represented in a spatial domain can be transformed using a discrete cosine transform. A 
message is then embedded into the transformed carrier image in step 104, using any 
appropriate technique for embedding a message onto a carrier signal. An example of a 
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transformed image into which a message can be embedded would be a JPEG image. If 
desired, the message can also be pre-encrypted before being embedded into the 
transformed image to further improve security. The image is then transformed back into 
the first domain in step 106 and made available for access by third parties in step 108. 
5 For a third party to extract the message the steps are essentially reversed. 

First the image is copied by the third party in step 110, and it is then transformed into the 
second domain in step 1 12 using the same transform performed in step 106. Finally, the 
message is extracted in step 1 14, again, using any appropriate technique that corresponds 
to the technique used in step 104 for originally embedding the message. If the message 
10 was pre-encrypted then another decryption step (not shown) will be necessary. 

Encrypted messages relying on the use of encryption keys are used in the 
methods discussed above. For example, if a pre-encrypted message is embedded into an 
image, then the recipient will need a key to decrypt the message. A technique for 
providing for secure exchanges of encrypted data such as encryption keys that is known in 
15 the art is the use of a trusted third party. The trusted third party essentially acts as a 

secure broker in exchanging data between two other parties. It is within the scope of this 
invention to exchange information, such as encryption keys, by use of a trusted third 
party. 

Although the invention has been described in detail with reference to 
20 certain illustrated embodiments, variations and modifications exist within the scope and 
spirit of the present invention as described and defined in the following claims. 
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CLAIMS 

1 . A method of data hiding comprising the steps of: 
providing a message; 

5 providing an encrypting sequence; 

generating an encrypted message based on the message and the encrypting 

sequence; 

providing a carrier signal that conveys information unrelated to the 
encrypted message; and 

10 embedding the encrypted message into the carrier signal by performing an 

exclusive-OR of the encrypted message with a first portion of the carrier signal. 

2. The method of claim 1, wherein the carrier signal is a digital image. 

3. The method of claim 2, wherein the first portion of the carrier 
signal is an LSB plane of the digital image. 

15 4. The method of claim 1, further comprising the step of embedding 

the first portion of the carrier signal into a second portion of the carrier signal. 

5. The method of claim 4, wherein the carrier signal is a digital image 
having a plurality of color planes, the first portion of the carrier signal is an LSB plane of 
a first color plane, and the second portion of the carrier signal is an LSB plane of a second 

20 color plane. 

6. The method of claim 1, further comprising the steps of transmitting 
the composite signal to a receiving location, extracting the encrypted message from the 
composite signal at the receiving location, and decrypting the encrypted message at the 
receiving location. 

25 7. The method of claim 1, wherein the step of generating an 

encrypted message includes generating the encrypting sequence based on an encrypting 
key and performing an exclusive-OR of the message with the encrypting sequence to 
generate the encrypted message. 

8. The method of claim 7, further comprising the steps of transmitting 

30 the composite signal to a receiving location, extracting the encrypted message from the 
composite signal at the receiving location, and decrypting the encrypted message at the 
receiving location based on the encrypting key. 
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9. The method of claim 1, wherein the step of providing a message 
comprised of providing a pre-encrypted message. 

10. The method of claim 9, further comprising the step of exchanging 
an encryption key for decrypting the pre-encrypted message using a trusted third party. 

5 1 1 . A method of data hiding comprising the steps of: 

providing an encryption key; 

generating an encryption sequence based on the encryption key; 
providing a carrier signal that conveys information unrelated to the 
encryption key; and 

10 embedding the encryption sequence into the carrier signal. 

12. The method of claim 11, wherein the encryption key is a public key 
for an asymmetric encryption algorithm. 

13. The method of claim 1 1, wherein the carrier signal is selected from 
the group comprising digital images, digital audio, and digital video. 

15 14. The method of claim 1 1, wherein the encryption sequence is 

substantially random. 

15. The method of claim 14, wherein the encryption sequence is 

generated based on a linear feedback shift register. 

16. The method of claim 1 1, wherein the step of embedding the 
20 encryption sequence includes performing an exclusive-OR of the encryption sequence 

with a portion of the carrier signal. 

17. The method of claim 11, further comprising the steps of 
transmitting the carrier signal including the embedded encryption sequence to a receiving 
location, extracting the encryption sequence from the composite signal at the receiving 

25 location, and deciphering the encryption sequence to obtain the encryption key at the 
receiving location. 

1 8 . The method of claim 1 7, further comprising the steps of encrypting 
a message using the encryption key to generate an encrypted message at the receiving 
location and transmitting the encrypted message from the receiving location. 

30 19. A method of data hiding comprising the steps of: 

embedding an encrypted message into a first portion of a carrier signal; 

and 
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embedding message extraction information into a second portion of the 
carrier signal for extracting the encrypted message from the first portion of the carrier 
signal. 

20. The method of claim 19, wherein the step of embedding an 

5 encrypted message includes performing an exclusive-OR of the encrypted message with 
the first portion of the carrier signal. 

21. The method of claim 20, wherein the step of embedding message 
extraction information includes performing an exclusive-OR of the first portion of the 
carrier signal with the second portion of the carrier signal. 

10 22. The method of claim 21, wherein the first and second portions of 

the carrier signal are first and second bit-planes of a digital image. 

23. A method of exchanging data hidden in a carrier signal comprising 

the steps of: 

generating a signal including hidden data by transforming a carrier signal 
1 5 from a first domain into a second domain, embedding a message into the carrier signal in 
the second domain, and transforming the carrier signal back from the second domain to 
the first domain; 

sending the signal including hidden data to a receiving location; and 
obtaining the message from the signal including hidden data at the 
20 receiving location by transforming the signal including hidden data into the second domain 
and extracting the message. 

24. The method of claim 23, further comprising the steps of encrypting 
the message prior to generating the signal including hidden data and decrypting the 
message after obtaining the message from the signal including hidden data. 

25 25. A data hiding apparatus comprising: 

an encryption sequence generator configured to generate an encryption 
sequence based on an encrypting key; 

an encrypted message generator configured to generate an encrypted 
message based on the encryption sequence and an input message; and 
30 an encrypted message embedder configured to embed the encrypted 

message into a carrier signal. 
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26. The method of claim 25, wherein the encryption sequence 
generator is configured to generate a substantially random encryption sequence. 

27. The method of claim 25, wherein the encrypted message generator 
is configured to perform an exclusive-OR of the input message with the encrypting 

5 sequence to generate the encrypted message. 

28. The method of claim 25, wherein the encrypted message embedder 
is configured to perform an exclusive-OR of the encrypted message with a portion of the 
carrier signed. 

29. The method of claim 28, wherein the encrypted message embedder 
10 is configured to replace a first LSB plane of the digital image with information based on a 

second LSB plane of the digital image and to perform an exclusive-OR of the encrypted 
message with the second LSB plane of the digital image. 



,1 I > 



WO 99/1 1020 PCT/US98/1 732 1 



1/4 



14. 



I 



16 

22'* 
20 



T 

JL 



40 



42 



T 
32 



34 



.12 



.31 



28 30 



18 



38 



36 



10 



FIG. I 



SUBSTITUTE SHEET (RULE 26) 

BNSDOCID: <WO 991 1020A1_I_> 



WO 99/1 1020 PCT7US98/17321 



2JU 



50 



Obtain Original Image 



I 



52 



Generate Secret Message 



I 



Generate Encryption 
Sequence From 
Encryption Key 



Encrypt Secret 
Message With 
Encryption Sequence 



i 



Embed Encrypted 
Message Into Image 



Place Image With 
Embedded Message 
On Public Network 



i 



If Secret Messoge Is 
Not Secret (i.e It Is 
Owner's Public Key) 



54 



56 



58 



60 



62 




64 



Place Encryption Key 
On Public Network 



FIG. 2 



BNSDOCID. <WO 9911020A1J_> 



SUBSTITUTE SHEET (RULE 26) 



WO 99/11020 



PCT/US98/17321 



3 / U 



66 



68 



.78 



70 



72 



76 



FIG. 3 



66 



( > 







1 


) » 

_80 





74 



^68 
< > - 



-82 



re, 



I 



-72 



.90 



84 



FIG. 4 



Q7 oc 96 OA 

9 7 98 g2 99 94 96 gy x g8 g2 gg »* 

QUJ—JM( f/4 W 

i i t i t 

* i I i I I 1— I 1 1 — I 



FIG. 5 



FIG. 6 



SUBSTITUTE SHEET (RULE 26) 



WO 99/11020 



PCT/US98/17321 



BNSDOCID: <WO 9911020A1J_> 



U J u 



Transform Image 
From First Domain 
To Second Domain 



i 



Embed Message 
Into Image 



Provide Image Over 
World Wide Web 



I 



Copy Image 



Transform Image 
From First Domain 
To Second Domain 



102 



104 



Transform Image 
From Second Domain 
To First Domain 



106 



108 



110 



112 



Extract Message 



114 



FIG. 7 



SUBSTITUTE SHEET (RULE 26) 



INTERNATIONAL SEARCH REPORT 



Int .tional Application No 

PCT/US 98/17321 



A. CLASSIFICATION OF SUBJECT MATTER 

IPC 6 H04L9/00 H04N1/32 



According to International Patent Classification (IPC) or to both national classification and IPC 



B. FIELDS SEARCHED 



Minimum documentation searched (classification system followed by classification symbols) 

IPC 6 H04L H04N 



Documentation searched other than minimum documentation to the extent that such documents are included in the fields searched 



Electronic data base consulted during the international search (name of data base and, where practical, search terms used) 



C. DOCUMENTS CONSIDERED TO BE RELEVANT 



Category J Citation of document, with indication, where appropriate, of the relevant passages 



YASUHIRO NAKAMURA ET AL: "A UNIFIED 

CODING METHOD OF DITHERED IMAGE AND TEXT 

DATA USING MICROPATTERNS" 

ELECTRONICS & COMMUNICATIONS IN JAPAN, 

PART I - COMMUNICATIONS, NEW YORK (US), 

vol. 72, no. 4, PART 01, 1 April 1989, 

pages 50-56, XP000080029 

see page 50, left-hand column, last 

paragraph - right-hand column, line 18 

see page 55, left-hand column, paragraph 

- right-hand column, paragraph 1 

-/-- 



Relevant to claim No. 



11,13,25 



Further documents are listed in the continuation of box C. 



Patent tamify members are listed in annex. 



J Special categories of cited documents : 

"A" document defining the general state of the art which is not 
considered to be of particular relevance 

"E" earlier document but published on or after the international 
filing date 

"L" document which may throw doubts on priority claim(s) or 
which is cited to establish the publication date of another 
citation or other special reason (as specified) 

"O" document referring to an oral disclosure, use. exhibition or 
other means 

"P" document published prior to the international filing date but 
later than the priority date claimed 



"T" later document published after the international filing date 
or priority date and not in conflict with the application but 
cited to understand the principle or theory underlying the 
invention 

"X" document of particular relevance; the claimed invention 
cannot be considered novel or cannot be considered to 
involve an inventive step when the document is taken alone 

"Y" document of particular relevance; the claimed invention 

cannot be considered to involve an inventive step when the 
document is combined with one or more other such docu- 
ments, such combination being obvious to a person skilled 
in the art. 

"&" document member of the same patent family 



Data of the actual completion of the international search 

5 February 1999 


Date of mailing ot the international search report 

15/02/1999 


Name and mailing address of the ISA 

European Patent Office, P.B. 5818 Patentlaan2 
NL - 2280 HV Rijswijk 
Tel. (+31-70) 340-2040. Tx. 31 651 epo nl. 
Fax: (+31-70) 340-3016 


Authorized officer 

Holper, G 



Form PCT/ISA/210 (second sheel) (July 1992) 



BNSDOCID: <WO 9911020A1_I_> 



page 1 of 2 



INTERNATIONAL SEARCH REPORT 



Int tional Application No 

PCT/US 98/17321 



C.(Continuation) DOCUMENTS CONSIDERED TO BE RELEVANT 



Category J Citation oi document, with indication. where appropriate, ot the relevant passages 



P,X 



EP 0 359 325 A (KONINKL PHILIPS 
ELECTRONICS NV ) 21 March 1990 
see abstract 

line 11 - line 34 
line 1 - line 18 
1 ine 39 - 1 ine 48 
1 ine 30 - column 5 , 
line 39 - line 50 
line 46 - column 8, 



see column 2, 

see column 3, 

see column 3, 

see column 4, 

see column 5, 

see column 7, 



line 22 



1 ine .5 



US 5 195 136 A (HARDY DOUGLAS A 
16 March 1993 

see column 4, 1 ine 21 - 1 ine 54 



ET AL) 



COX I J ET AL: "SECURE SPREAD SPECTRUM 
WATERMARKING FOR MULTIMEDIA" 
IEEE TRANSACTIONS ON IMAGE PROCESSING, NEW 
YORK (US), 

vol. 6, no. 12 , December 1997, pages 
1673-1687, XP000199950 

see page 1677, right-hand column, line 7 - 
page 1678, left-hand column, line 10 

PODILCHUK C I ET AL: "DIGITAL IMAGE 
WATERMARKING USING VISUAL MODELS" 
PROCEEDINGS OF THE SPIE, 
vol. 3016, 10 February 1997, pages 
100-111, XP000199957 

see page 103, line 22 - page 104, line 11; 
figure 1 



Relevant to claim No. 



1,3,16, 
19,20 



1,14-16, 
26,27 



23 



23 



Form PCT/1SA/210 (continuation ot second sheet) (July 1992) 
BNSDOCID: <WO 991 1020A1_L> 



page 2 of 2 



INTERNATIONAL SEARCH REPORT 

Information on patent family members 



Intt ional Application No 

PCT/US 98/17321 



Patent document 
cited in search report 



Publication 
date 



Patent family 
member(s) 



Publication 
date 



EP 0359325 



21-03-1990 



NL 
DE 
DE 
DE 
DE 
EP 
HK 
JP 
US 



8802291 
68919958 
68919958 
68928493 
68928493 

0545915 
76796 

2119446 

5146457 



US 5195136 



16-03-1993 



NONE 



17-04- 
26-01- 
29-06- 
22-01- 
04-06- 

09- 06- 

10- 05- 

07- 05- 

08- 09- 



1990 
1995 
1995 
1998 
1998 
1993 
1996 
1990 
1992 



Form PCT/TSA/210 (patent tantiy annex) (July 1992) 



BNSDOCID: <WO 9911020A1_ 



WO 99/1 10SD 



PCT/US9a/17321 



1/ 4 




FIG. I 



BNSDOCID: <WO 991 1020A1TI_> 



SUBSTTTUTE SHEET (RULE 28) 



PCT/U5!?8/173il 



2/4 



50 



Obtain Drjgina? Image 



I 



52 



Generate Seerel Massoga 



I 



General* encryption 
Sequ«fu» From 
Encryption Key 



Encrypt Secret - 
Meewge With 
Encryption Sequenc* 



Erobad Eiieryptad 
Me$6og« Into Image 



i 



Place Image With 
Embedded Mmoga 

On Public Network 



54 



56 



1 58 



6D 



62 



If Secret Message la 
M Seen* (U It Is 
Owner' b Public Key) 




04 



Place Encryption K«y 
On Public Network 



FIG. 2 



8UB5TITUTE SHEET (RULE 26) 



r 



i 



WOW/ 1 10 24) 



3/4 



PCT/UB9SU73£1 



63 



70 



I 



72 



76 



FIG. 3 



,66 



•7H 



■ .86 



,66 




<. > — 





i 



72 



-90 



84 



FIG. 4 



,7+ 



07 aft 9 £ 9* 

V 98 o, 99 94 . 9e 97 9B 92 t Bfl I 



FIG. 5 



FIG. 6 



BNSDOCID: <WO 991 1020A1TI_> 



SUBSTITUTE SHEET (&ULE 28) 



WOW11020 



4/4 



Transform Image 
From First Domain 
Ta Second Domain 



I 



Embed Mesgage 
Into Image 



Transform Jmqgft 
Fmrfl S*cor>d Domain 
To First Derrwin 



Provide Imoga Over 
World Wide W«b 



Ccpy Image 



transform Image 
From Pint Domain 
To Second Domain 



Extract Massage 



.102 



t04 



JOB 



.100 



1 10 



.112 



.114 



FIG. 7 



SUBSTITUTE SHEET (RULE 25) 

BNSDOCID: <WO 991 1020AlTI_> 



